Skip to content

mega: fall back to password login when stored session is expired - #10006

Open
xiao115255 wants to merge 1 commit into
rclone:masterfrom
xiao115255:claude/issue-9952
Open

xiao115255 wants to merge 1 commit into
rclone:masterfrom
xiao115255:claude/issue-9952

Conversation

@xiao115255

Copy link
Copy Markdown

What & Why

When a mega: remote is configured with a stored session (session_id and master_key) and that session has expired server-side, LoginWithKeys fails with the ESID or EAGAIN sentinel after go-mega's internal retries exhaust. Until now rclone surfaced this as login with previous auth keys failed and gave up, even though a valid user and pass were still configured, leaving the user to run rclone config reconnect manually. Repeated MEGA ‑3 responses eventually corrupt the response buffer and the user sees unexpected end of JSON input.

Extracted the login flow into a login method that falls back to MultiFactorLogin when the stored session is rejected as invalid or expired, and persists the fresh session in the config so subsequent runs don't repeat the failed login. isSessionExpiredErr identifies the EAGAIN (‑3) and ESID (‑15) sentinels as the signals to re-authenticate.

Addresses #9952 acceptance criteria:

  • Stop rclone from looping on a stale stored session.
  • Use the configured username and password as the recovery path.
  • Update the stored session in the config so the next run does not hit the same path.

How Tested

  • go build ./backend/mega/ and go vet ./backend/mega/ — clean.

  • RCLONE_CONFIG=/notfound go test -count=1 ./backend/mega/ — pass, including the new TestIsSessionExpiredErr table test which pins down EAGAIN / ESID (and wrapped variants) as session-expired, while EACCESS (‑11), EARGS, EOVERQUOTA, and unrelated errors are not.

  • End-to-end repro on a mega: remote with a bogus session_id:

    Before (master):

    DEBUG : mega root '': Using previously stored session ID and master key to initialize the Mega API
    CRITICAL: Failed to create file system for "mega-test:": login with previous auth keys failed: Invalid or expired user session, please relogin
    

    After (this branch):

    DEBUG : mega root '': Using previously stored session ID and master key to initialize the Mega API
    DEBUG : mega root '': Stored session is invalid (Invalid or expired user session, please relogin); re-authenticating with username and password
    CRITICAL: Failed to create file system for "mega-test:": stored session was invalid and login with username and password failed: Invalid or expired user session, please relogin
    

    The test uses a non-existent user so MEGA also rejects the password fallback; with valid credentials, MultiFactorLogin succeeds and lsd proceeds. The point is the control flow: when LoginWithKeys fails with ESID / EAGAIN, the backend now recovers via the password rather than giving up immediately.

  • Full backend tests against a real TestMega: remote (the integration test suite) could not be run here as no MEGA credentials are available. The new unit test covers the error-classification behavior the fallback depends on; the auth path itself is unchanged on success and is exercised by the existing TestIntegration against a real remote in the maintainer's CI.

Known Limitations

  • This change recovers the init-time path (the scenario in the issue log). Mid-session expiry — where init succeeds and the session is invalidated later while listing / uploading — is not wrapped in an automatic re-login; the cached srv still holds the now-stale sid/k from go-mega, which a follow-up could refresh by calling login from shouldRetry or from findRoot. Filing that as a separate issue if the maintainer wants it.
  • EAGAIN is a "try again" sentinel; in the rare case MEGA returns -3 for a transient server overload rather than an expired session, this fix triggers one extra password login attempt. The cost is bounded (one attempt, no loop), and the issue's debug log confirms -3 here is in fact the expired-session case.

AI Disclosure

This PR was prepared with AI assistance (Claude Code), reviewed and submitted by @xiao115255.

 rclone#9952

When a mega remote is configured with a stored session (session_id and
master key) and that session has expired on the server side, LoginWithKeys
fails with the ESID or EAGAIN sentinel after go-mega's internal retries
exhaust. Previously rclone surfaced this as "login with previous auth
keys failed" and gave up, even though valid user/pass credentials were
still configured, leaving the user to run rclone config reconnect manually.

Extract the login flow into a login method which falls back to
MultiFactorLogin when the stored session is rejected as invalid or
expired, and persists the fresh session in the config so subsequent runs
don't repeat the failed login. Add isSessionExpiredErr to identify the
sentinels that mean the stored session is no longer usable, and unit
tests pinning that classification down.

Fixes rclone#9952

Co-Authored-By: Claude Code <noreply@anthropic.com>
@xiao115255
xiao115255 requested a review from ncw as a code owner September 29, 2026 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant